Sara Friedman

Sara Friedman joined Inside Cybersecurity in February 2020. Previously, she covered government IT for GCN and education technology for THE Journal and Campus Technology. She graduated from Ithaca College with bachelor’s degrees in journalism and politics.

Connections
Archived Articles
Daily News | June 30, 2022

The Pentagon is planning to issue a final rule in December establishing a regime for Defense Department acquisition officials to conduct assessments of a contractor's compliance with NIST Special Publication 800-171.

Daily News | June 29, 2022

Pentagon cyber chief David McKeown says there are ongoing discussions to create a "cyber secure framework" for the defense industrial base that will go beyond the CMMC program and be based on the NIST cybersecurity framework.

Daily News | June 29, 2022

The Pentagon's acquisition office has issued a memorandum reminding acquisition officials of the Defense Department's current standard for the handling of controlled unclassified information and potential remedies for non-compliance.

Daily News | June 23, 2022

The House Armed Services Committee has approved its version of the fiscal 2023 defense authorization bill, including provisions to create an “information collaboration environment” at CISA and directing DHS and CISA to provide details to Congress on cyber incident response responsibilities.

Daily News | June 17, 2022

The House Armed Services Committee is set to mark up an annual defense policy bill that includes creation of the "Cyber Threat Information Collaboration Environment Program," a reworked version of a Cyberspace Solarium Commission proposal viewed as an important component for government-industry interaction.

Daily News | June 8, 2022

The House Armed Services Committee will take the first steps today in considering cyber proposals for the fiscal year 2023 defense authorization bill, including requiring a congressional briefing from Pentagon officials on their cyber certification program and Software Bill of Materials efforts.

Daily News | June 7, 2022

The accreditation body behind the Pentagon's Cybersecurity Maturity Model Certification program announced a rebrand and new website today, aiming to align with the organization's future and offering new opportunities to bring CMMC to civilian agencies and international entities.

Daily News | June 3, 2022

The Defense Department and the Cybersecurity and Infrastructure Security Agency have published a process guide to help agencies evaluate security when it comes to acquiring fifth-generation telecom technology, using the NIST risk management framework.

Daily News | May 16, 2022

The Defense Department faces a calculated risk in terms of starting up third-party assessments under the Cybersecurity Maturity Model Certification program for early adopters, according to contracting attorney Robert Metzger, who sees ongoing work to finalize changes to the Pentagon's acquisition rules as one barrier for the delayed interim launch.

Daily News | May 11, 2022

The Defense Department is accelerating by two months its plans to implement changes to the Cybersecurity Maturity Model Certification program, with the release of two interim final rules now expected in March 2023 and requirements to start showing up in contracts 60 days after the rules are published under a three-year rollout plan.

Daily News | May 11, 2022

The National Institute of Standards and Technology this year will issue a "pre-call" for public comments on updates to four publications concerning the security of controlled unclassified information.

Daily News | May 9, 2022

The Pentagon's interest in enabling companies to reach Cybersecurity Maturity Model Certification compliance through FedRAMP-approved cloud offerings is generating conversations within Microsoft and managed service providers on how such an offering could work in practice.

Daily News | May 4, 2022

Cybersecurity Maturity Model Certification assessment organizations are waiting on several details to fall into place so they can start conducting official assessments for companies that want to compete for defense contracts, but stakeholders say uncertainty over rulemaking timing is not impacting demand from companies wanting to be early adopters.

Daily News | April 28, 2022

Cybersecurity Maturity Model Certification Accreditation Body CEO Matthew Travis says he expects the Defense Department in early August to allow official third-party assessments under the voluntary cybersecurity certification program, kicking off the start of an interim period where company certifications will be accepted when the CMMC requirements start showing up in contracts next year.

Daily News | April 25, 2022

The Defense Department is moving aggressively to implement zero-trust architectures across the services and agencies by the end of 2027, according to Pentagon cyber chief David McKeown, who says the move has been accelerated by President Biden's cyber executive order.

Daily News | April 21, 2022

The Defense Department is in the early stages of determining whether it can work with industry partners to develop cloud service offerings that can help contractors meet Cybersecurity Maturity Model Certification requirements, according to Pentagon cyber chief David McKeown.

Daily News | April 21, 2022

Two rulemakings to implement the Pentagon's Cybersecurity Maturity Model Certification program are expected in May 2023, according to CMMC Director Stacy Bostjanick, who says they could be followed by an additional rule to establish how reciprocity will work with international partners.

Daily News | April 15, 2022

The National Institute of Standards and Technology has added two new data formats intended to improve the usability of four publications that are foundational to the Pentagon's cyber certification program.

Daily News | April 14, 2022

The Pentagon will start the formal process in July to make regulatory changes to its Cybersecurity Maturity Model Certification program with the submission of a new rulemaking to the White House Office of Management and Budget for review, according to a Pentagon spokesman.

Daily News | April 13, 2022

The use of waivers for the Pentagon’s Cybersecurity Maturity Model Certification program will be determined based on the needs of acquisition officials for specific contracts, not the qualifications of a company bidding for contract selection, according to CMMC director Stacy Bostjanick.

Not a subscriber? Sign up for 30 days free access to exclusive, behind-the-scenes reporting on defense policy and procurement.